Senior Security Engineer - DART (Detection and Response Team)

JobCubby

Hinoba-an

On-site

PHP 1,200,000 - 1,800,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Rippling is seeking an experienced Security Engineer to join our Detection and Response Team (DART). You will help scale our incident response, improve processes, and build detection infrastructure across production and corporate environments.

The role requires strong cloud security, threat hunting, and automation skills, with excellent communication to stakeholders. Responsibilities include responding to events, developing runbooks, leading threat-hunting efforts, and building tools to collect

Qualifications

  • 7+ years of full-time security engineering experience including monitoring, incident response and threat hunting in cloud environments.
  • Defensive security practitioner who understands offensive security and real-world compromise scenarios.
  • Experience leading complex investigations with many stakeholders.
  • Excellent communication with internal and external stakeholders at all levels.
  • Expertise in AWS security controls and services.
  • Experience coding for automation, alert enrichment and detections.
  • Knowledge of adversary TTPs and MITRE ATT&CK framework.
  • Hands-on data analysis, modeling and correlation at scale.
  • OS forensics experience: macOS, Windows and Linux.
  • Experience with current SIEM and SOAR platforms.
  • Experience building tools and automation with DevOps toolsets and languages.
  • Understanding malware functionality and persistence mechanisms.
  • Ability to analyze endpoint, network and application logs for anomalies.

Responsibilities

  • Respond to security events, triage, investigate incidents and communicate findings to stakeholders.
  • Improve detection, response processes, and tooling post-incident debriefs.
  • Develop and run tooling to collect telemetry from cloud production systems.
  • Automate workflows to speed up detection and response times.
  • Build and optimize detection rules to focus on meaningful alerts.
  • Develop runbooks and incident playbooks for detections.
  • Lead threat hunting activities and surface attacker signals for security controls.

Skills

Security monitoring
Incident response
Threat hunting
AWS security
Automation coding
MITRE ATT&CK
Data analysis
Forensics
SIEM & SOAR
DevOps tooling

Tools

SIEM
SOAR
DevOps toolchains

Job description

About the role

We are looking for an experienced Security Engineer to join our Detection and Response Team (DART). You will help us build out a world class incident response function that will navigate challenging security incidents, drive process improvement, develop an open culture where we grow from our mistakes as an organization. In this role, you will also build the tools and detection infrastructure that we need to scale our detection and response capability across all threats to our Production and Corporate environments.

What you will do
  • Respond to security events, triage, perform investigations, incident analysis, and communicate clearly and efficiently to stakeholders
  • Contribute to improving processes, procedures, and technologies used for detection and response, enabling us to improve after each incident
  • Develop and run tools to gather security telemetry data from cloud production systems
  • Automate workflows and improve identification and response time for security events
  • Build and optimize detection rules, allowing us to spend our cycles on the alerts that matter
  • Develop runbooks and incident playbooks for new and existing detections
  • Lead Threat hunting practices, suggest product and infrastructure signals to surface attacks and incorporate findings into security controls
What you will need
  • 7+ years of full-time experience as a security engineer, including security monitoring, incident response, and threat hunting in a cloud environment
  • A defensive practitioner who understands offensive security and, the actual scenarios that lead to compromise
  • Prior experience leading complex investigations with a large number of stakeholders
  • Strong communication skills and a proven track record of communicating with internal and external stakeholders at all levels.
  • Expertise on AWS security controls and services.
  • Experience leveraging coding for automation, alert enrichment and detections.
  • Knowledge of adversary tactics, techniques, and procedures (TTPs) and MITRE ATT&CK principles
  • Hands‑on experience with data analysis, modeling, and correlation at scale
  • Operating systems internals and forensics experience for macOS, Windows & Linux
  • Domain experience managing and working with current SIEM and SOAR platforms
  • Experience developing tools and automation using common DevOps toolsets and programming languages
  • Understanding of malware functionality and persistence mechanisms
  • Ability to analyze endpoint, network, and application logs for anomalous events
Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accomodations@rippling.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Detection & Response (DART)
Senior Security Engineer - Detection & Response (DART)

JobCubby • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
Senior Security Engineer – Threat & Incident Response
Senior Security Engineer – Threat & Incident Response

PDAX • Pasig

On-site
PHP 900,000 - 1,300,000
Security Operations Lead
Security Operations Lead

Fireworks • San Mateo

On-site
PHP 1,800,000 - 3,200,000
Cybersecurity Senior Analyst
Cybersecurity Senior Analyst

Thumbtack Philippines • Philippines

On-site
PHP 1,200,000 - 2,400,000
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elasticsearch B.V. • España

On-site
PHP 4,866,000 - 7,698,000
Health coverage
Flexible locations and schedules
Generous vacation days
+3
Senior Officer, Security Engineering
Senior Officer, Security Engineering

PDAX • Pasig

On-site
PHP 900,000 - 1,300,000
Senior Consultant – Digital Forensics & Incident Response (DFIR)
Senior Consultant – Digital Forensics & Incident Response (DFIR)

PM Consulting • Philippines

Hybrid
PHP 900,000 - 1,500,000
Associate Principal, Response Operations, Cyber Risk
Associate Principal, Response Operations, Cyber Risk

Kroll • Manila

On-site
PHP 1,100,000 - 1,300,000
Sr Cybersecurity Analyst
Sr Cybersecurity Analyst

Dexcom Inc. • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Security Risk Management
Security Risk Management

LaPieza • Mexico

On-site
PHP 4,991,000 - 6,862,000